Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens. Since there is no nonce validation or time limit on requests, the attack can be performed indefinitely. Dell recommends customers to upgrade at the earliest opportunity
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell secure Connect Gateway |
|
| CPEs | cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:application:*:*:* cpe:2.3:a:dell:secure_connect_gateway:*:*:*:*:virtual:*:*:* |
|
| Vendors & Products |
Dell
Dell secure Connect Gateway |
Wed, 09 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Replay Attack Enables Remote Admin Access |
Wed, 09 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens. Since there is no nonce validation or time limit on requests, the attack can be performed indefinitely. Dell recommends customers to upgrade at the earliest opportunity | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published: 2026-09-09T11:47:41.245Z
Updated: 2026-09-09T12:54:00.206Z
Reserved: 2026-08-25T21:04:22.134Z
Link: CVE-2026-80172
Updated: 2026-09-09T12:53:56.909Z
Status : Analyzed
Published: 2026-09-09T12:17:15.057
Modified: 2026-09-09T20:14:34.570
Link: CVE-2026-80172
No data.